While organizations are facing increased pressure from external cyberthreats, they must also consider attacks that can originate from within the organization. Insider threat attacks are executed by employees who utilize the access they are provided by an organization to perform malicious actions, such as data exfiltration. Previous works have proposed methods for detecting insiders based on analyzing the actions users perform in a work environment. In this work we propose to identify “at-risk” employees using solely “Big-Five” personality factors, known as OCEAN or CANOE, as an indicator of risk. We perform experiments using the CMU-CERT r4.2, CMU-CERT r5.2, TWOS, and a custom dataset, where we compare clustering results of 4 methods and detection results of 40 classification methods, with 25 sampling techniques. This work demonstrates the effectiveness, feasibility and limitations of using the psychometric profile as a method to identify potential insider threats. We suggest future work to explore the temporality of an employee’s psychometric profile and consider how its evolution over time can be used in dynamic risk assessment.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

From Traits to Threats: Learning Risk Indicators of Malicious Insider Using Psychometric Data

  • N’Famoussa Kounon Nanamou,
  • Christopher Neal,
  • Nora Boulahia-Cuppens,
  • Frédéric Cuppens,
  • Anis Bkakria

摘要

While organizations are facing increased pressure from external cyberthreats, they must also consider attacks that can originate from within the organization. Insider threat attacks are executed by employees who utilize the access they are provided by an organization to perform malicious actions, such as data exfiltration. Previous works have proposed methods for detecting insiders based on analyzing the actions users perform in a work environment. In this work we propose to identify “at-risk” employees using solely “Big-Five” personality factors, known as OCEAN or CANOE, as an indicator of risk. We perform experiments using the CMU-CERT r4.2, CMU-CERT r5.2, TWOS, and a custom dataset, where we compare clustering results of 4 methods and detection results of 40 classification methods, with 25 sampling techniques. This work demonstrates the effectiveness, feasibility and limitations of using the psychometric profile as a method to identify potential insider threats. We suggest future work to explore the temporality of an employee’s psychometric profile and consider how its evolution over time can be used in dynamic risk assessment.